Share via

The Purview Workload Content Administrator role for the <redacted> directory was assigned outside of PIM

Adrian 25 Reputation points
2026-05-14T02:00:07.17+00:00

I have the following messages coming in thick and fast - 15 emails so far in the last 15 minutes - I can't see anything added ? do we have as security issue ?

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Answer accepted by question author

Vasil Michev 126.8K Reputation points MVP Volunteer Moderator
2026-05-14T05:59:50.4+00:00

Ignore them, most tenants using Purview and PIM have received the same. It's indeed a "noise" event but nothing to be concerned about. Just Microsoft doing Microsoft things.

Was this answer helpful?

7 people found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. Somarribas, Josue 0 Reputation points
    2026-05-14T22:22:51.3533333+00:00

    Hello everyone,

    To identify the user who assigned the role, you can review the activity logs in Microsoft Entra. Navigate to Microsoft Entra and access Audit Logs within the Monitoring and Health section.

    Apply a filter for the activity type "Add member to role" to locate the relevant entries. The results will display detailed records of role assignments.
    User's image

    User's image

    Additionally, this process relies on standard Microsoft developer tooling and logging capabilities.
    User's image

    Was this answer helpful?


  2. AI answer

    2026-05-14T02:00:19.0966667+00:00

    Those emails are Privileged Identity Management (PIM) security alerts indicating that the Purview Workload Content Administrator role is being assigned directly in Microsoft Entra ID instead of via PIM. This is treated as a high‑severity event because assignments made outside PIM are not properly monitored and can indicate misuse or an active attack.

    What the alert means:

    • The alert is “Roles are being assigned outside of Privileged Identity Management” for a Microsoft Entra role.
    • PIM raises this when a privileged role (here, Purview Workload Content Administrator) is assigned outside PIM.
    • Emails for this alert go to Privileged Role Administrators, Security Administrators, and Global Administrators who have PIM enabled.
    • Multiple or repeated assignments can generate many emails in a short period.

    Immediate checks and actions:

    1. Review the alert details in PIM
      • Go to Privileged Identity Management → Alerts → “Roles are being assigned outside of Privileged Identity Management”.
      • Review the list of users/service principals that have been assigned the Purview Workload Content Administrator role outside PIM.
    2. Validate each assignment
      • Confirm whether each listed assignment is expected and approved.
      • If any are unexpected, treat as a potential security incident.
    3. Remediate suspicious or non‑compliant assignments
      • For any user or identity that should not have this role, remove them from the privileged role (this is the in‑portal mitigation action described for this alert).
      • Then, if access is still required, re‑assign the role via PIM as eligible or active according to policy.
    4. Investigate where the assignments are coming from
      • Determine which admin, script, or application is assigning the role directly in Entra ID (for example, via portal, Azure Resource Manager API, or automation).
      • Update processes and tools so that privileged role assignments are done through PIM only.
    5. Tune notifications if needed (after investigation)
      • If the assignments are legitimate but frequent, the alert and its accompanying email notification can be enabled or disabled in alert settings.
      • Do this only after confirming there is no ongoing security issue.

    Is this a security issue?

    • By design, this alert is High severity because assigning privileged roles outside PIM bypasses standard monitoring and controls.
    • It does not automatically mean a confirmed breach, but it does require immediate review of who received the role and why.

    If unexpected assignments are found, follow the organization’s incident response process (containment, investigation of audit logs, and verification of admin accounts and automation).


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.